Microsoft SharePoint Zero-Day Cyber Attack
Analysis based on 6 articles · First reported Jul 21, 2025 · Last updated Jul 21, 2025
The widespread cyberespionage operation targeting Microsoft's server software has a negative impact on the cybersecurity industry and the affected organizations, including major industrial firms, banks, auditors, healthcare companies, and government entities in the United States and Germany. This event highlights the ongoing threat of zero-day vulnerabilities and the need for robust cybersecurity measures, potentially increasing demand for cybersecurity services from companies like Eye Security and Sophos.
A sweeping cyberespionage operation has compromised approximately 100 organizations globally by exploiting a 'zero-day' vulnerability in Microsoft's self-managed SharePoint server software. The hacks allow spies to penetrate vulnerable servers and potentially install backdoors for continuous access. Eye Security, a Netherlands-based cybersecurity firm, discovered the campaign and, with the Shadowserver Foundation, identified the victims, primarily in the United States and Germany, including government agencies. Microsoft has issued security updates, urging customers to install them. The United States — Federal Bureau of Investigation and Britain's United Kingdom — National Cyber Security Centre are aware of the attacks. While the perpetrators are not definitively identified, Alphabet Inc.'s Google has linked some hacks to a 'China-nexus threat actor'. The incident underscores the significant cybersecurity risks faced by various sectors, with over 8,000 servers potentially compromised.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard